Re: Shorewall bug

2004-06-29 Thread Johann Spies
On Tue, Jun 29, 2004 at 10:03:50AM +0200, Javier Fernández-Sanguino Peña wrote: > On Tue, Jun 29, 2004 at 09:28:00AM +0200, Johann Spies wrote: > > > > Does anyone know whether there are woody packages for these corrected > > versions? > > Actually no, I'm not sure wether the Security Team will p

Re: Shorewall bug

2004-06-29 Thread Javier Fernández-Sanguino Peña
On Tue, Jun 29, 2004 at 09:28:00AM +0200, Johann Spies wrote: > > Does anyone know whether there are woody packages for these corrected > versions? Actually no, I'm not sure wether the Security Team will publish a DSA realted to this issue since it's non-critical. For more information see #2563

Shorewall bug

2004-06-29 Thread Johann Spies
I have seen the following on the Shorewall Mailing list: --- Javier Fernández-Sanguino Peña has discovered an exploitable vulnerability in the way that Shorewall handles temporary files and directories. The vulnerability can allow a non-root user to cause arbitrary files on the system to be ov